StackRadar

CVE-2026-18508

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,832 indexed, latest versions
Container images
2,553
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,554 of 17,832 indexed charts deploy, on 2,553 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,553
OSV records
DEBIAN-CVE-2026-18508UBUNTU-CVE-2026-18508ECHO-94ec-2dbe-8b73

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,623
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,628
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
tar@1.29b-2ubuntu0.2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

9,357
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

8,128

Container images carrying it

2,553 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
tar@1.35+dfsg-3.1
no fix listed
1
egorz/netology-diploma-web-app:4.05627a54bd1ad
tar@1.34+dfsg-1.2
no fix listed
1
elastic/apm-server:7.17.6c7a1c63257d0
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
tar@1.29b-2ubuntu0.1
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
tar@1.29b-2ubuntu0.1
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
tar@1.29b-2ubuntu0.1
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
tar@1.29b-2ubuntu0.1
no fix listed
1
elastiflow/flow-collector:7.26.0fee67842e16b
tar@1.35+dfsg-3build1
no fix listed
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
tar@1.35+dfsg-3.1
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
emqx/emqx:5.8.935b46f7aa7a0
tar@1.35+dfsg-3.1
no fix listed
1
emqx/emqx-enterprise:6.3.15ecbf93d04e3
tar@1.35+dfsg-3.1+dhi1
no fix listed
1
enclavenetworks/enclave:latest0a99759300d1
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
tar@1.29b-2ubuntu0.2
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.38.4447f857a0146
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.34-latestcfc0678bc03c
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.39.0d59f7f5fa10c
tar@1.34+dfsg-1ubuntu0.1.22.04.4
no fix listed
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
tar@1.29b-2ubuntu0.2
no fix listed
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
tar@1.29b-2ubuntu0.3
no fix listed
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
tar@1.35+dfsg-3.1
no fix listed
1
erigontech/erigon:v2.61.288706754b627
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
erigontech/erigon:latest8cd3fbcbb35d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
erlangsolutions/mongooseim:6.6.0cc5bf032931f
tar@1.35+dfsg-3build1
no fix listed
1
erudikaltd/para:latest_stable235e0bc53da2
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
escaping/core-keeper-dedicated:latest87fa79255962
tar@1.35+dfsg-3.1
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
tar@1.35+dfsg-3.1
no fix listed
1
esphome/esphome:2026.9.09959730a04c7
tar@1.35+dfsg-3.1
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
tar@1.34+dfsg-1.2
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
tar@1.34+dfsg-1.2
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
tar@1.34+dfsg-1.2
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
tar@1.35+dfsg-3.1
no fix listed
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
tar@1.28-2.1ubuntu0.1
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
tar@1.34+dfsg-1.2
no fix listed
1
ethersphere/beekeeper:lateste3bc0da9ffde
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ethpandaops/assertoor:latest1efa2fba6711
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/buildoor:mainb3dc726f8ba5
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/dora:mastere7c0ed360365
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/eleel:mainb8f1b707aee0
tar@1.35+dfsg-3build1
no fix listed
1
ethpandaops/forky:debian-latestc937f4ba737c
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/observoor:masterc7e5055defcb
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/spamoor:latestc8c6ab0816c4
tar@1.35+dfsg-3.1
no fix listed
1
factoriotools/factorio:latest18c07a80cacc
tar@1.35+dfsg-3.1
no fix listed
1
factoriotools/factorio:stable4ec5fea2e06b
tar@1.35+dfsg-3.1
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.